Swammers8/WBCE-v1.6.3-Authenticated-RCE

Swammers8/WBCE-v1.6.3-Authenticated-RCE

Releases0

CVE History

CVEPublishedCVSS v3CVSS v2
8.8 HIGH

WBCE CMS version 1.6.3 and prior contains an authenticated remote code execution vulnerability that allows administrators to upload malicious modules. Attackers can craft a specially designed ZIP module with embedded PHP reverse shell code to gain remote system access when the module is installed.